I will do a security audit of your web app and cloud setup


Vetted Pro
Top Rated
Vetted by Fiverr Pro
Joshua D was selected by the Fiverr Pro team for their expertise.
About this gig
Your app is live. Is it actually secure?
Most breaches don't come from anything exotic. They come from an over permissive IAM role, a secret committed to a repo, a database open to the world, or an auth check that was never quite finished.
What I check:
- Cloud and infrastructure on AWS, GCP or Azure: IAM, network exposure, encryption, backups, logging
- Application layer: authentication, authorisation, injection, dependency vulnerabilities
- Secrets and credentials: what sits in your repo, env files and CI
- Data protection: what is stored, where, and who can reach it
What you get:
A written report of every finding ranked by real risk, with a fix plan you can hand to any developer. Not a raw scanner dump.
Ten years in tech, AWS certified, and I build the systems I review, so the fixes are practical rather than theoretical.
Message me before ordering with what you are running and I will tell you honestly whether it is worth auditing.
Get to know Joshua D
Vetted Pro
Making your Application Ideas a Reality
Top Rated
Joshua D is part of the Fiverr Pro catalog and has been hand-picked by a dedicated Fiverr Pro team for their skills and expertise.
Vetted for
Software Development
- FromUnited Kingdom
- Member sinceJul 2022
- Avg. response time2 hours
- Last delivery1 week
Languages
English
My Portfolio
Other Software Development Services I Offer
FAQ
Do you do penetration testing as well as an audit?
Yes, within a scope we agree in writing first. Most buyers get more value from a configuration and code level review, because that is where the real problems usually sit. If you need certified pentesting for a compliance sign off, tell me and I will say so honestly.
What access do you need from me?
Read only wherever possible. Usually a read only cloud account or exported configuration, access to the repository, and a short call to walk through how the app is meant to work. I will never ask you to send credentials over email.
Do you fix the issues or just report them?
The audit covers finding, ranking and explaining how to fix each issue. The fixes themselves are quoted separately once you have seen the report, so you decide what is worth doing. Plenty of clients hand the report to their own developer instead.
